- EPSS 0.1%
- Veröffentlicht 27.10.2025 14:39:41
- Zuletzt bearbeitet 30.10.2025 15:05:50
Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate allows authentication attempts which may enable brute force login attacks.
CVE-2024-25573
- EPSS 0.13%
- Veröffentlicht 15.06.2025 15:25:38
- Zuletzt bearbeitet 16.06.2025 12:32:18
Unsanitized user-supplied data saved in the PingFederate Administrative Console could trigger the execution of JavaScript code in subsequent user processing.
CVE-2025-22854
- EPSS 0.09%
- Veröffentlicht 15.06.2025 15:00:06
- Zuletzt bearbeitet 16.06.2025 12:32:18
Improper handling of non-200 http responses in the PingFederate Google Adapter leads to thread exhaustion under normal usage conditions.
CVE-2025-21085
- EPSS 0.09%
- Veröffentlicht 15.06.2025 14:25:39
- Zuletzt bearbeitet 16.06.2025 12:32:18
PingFederate OAuth2 grant duplication in PostgreSQL persistent storage allows OAuth2 requests to use excessive memory utilization.
CVE-2024-22477
- EPSS 0.14%
- Veröffentlicht 09.07.2024 23:15:10
- Zuletzt bearbeitet 21.11.2024 08:56:21
A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.
CVE-2024-22377
- EPSS 0.37%
- Veröffentlicht 09.07.2024 23:15:10
- Zuletzt bearbeitet 21.11.2024 08:56:09
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
CVE-2024-21832
- EPSS 0.14%
- Veröffentlicht 09.07.2024 23:15:10
- Zuletzt bearbeitet 21.11.2024 08:55:05
A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.
CVE-2023-40148
- EPSS 0.08%
- Veröffentlicht 10.04.2024 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:18:52
Server-side request forgery (SSRF) in PingFederate allows unauthenticated http requests to attack network resources and consume server-side resources via forged HTTP POST requests.
CVE-2023-40545
- EPSS 0.07%
- Veröffentlicht 06.02.2024 18:15:58
- Zuletzt bearbeitet 21.11.2024 08:19:41
Authentication bypass when an OAuth2 Client is using client_secret_jwt as its authentication method on affected 11.3 versions via specially crafted requests.
CVE-2023-39219
- EPSS 0.17%
- Veröffentlicht 25.10.2023 18:17:28
- Zuletzt bearbeitet 21.11.2024 08:14:56
PingFederate Administrative Console dependency contains a weakness where console becomes unresponsive with crafted Java class loading enumeration requests